Splunk® Enterprise

Release Notes

Download manual as PDF

This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Download topic as PDF

6.3.7

Splunk Enterprise 6.3.7 was released on September 7, 2016.

The following issues have been resolved in this release. For information about security fixes not related to authentication or authorization, refer to the Splunk Security Portal.

Issues are listed in all relevant sections. Some issues appear more than once.

Search issues

Date resolved Issue number Description
2016-08-17 SPL-123066, SPL-124248, SPL-126820, SPL-124246, SPL-124247 A search using mvexpand command returns a Memory Threshold warning but no corresponding value exists in limits.conf
2016-08-12 SPL-119340, SPL-126569, SPL-126648 admin/summarization return wrong values for latest and size
2016-08-08 SPL-123961, SPL-125803, SPL-125804 splunk_server_group field does not exist in tstats command
2016-07-28 SPL-112018, SPL-123777, SPL-123770, SPL-123771 Lookup Tables With Zero Bytes Are Not Replicated in Search Head Clustering

Saved search, alerting, scheduling, and job management issues

Date resolved Issue number Description
2016-08-17 SPL-126266, SPL-126220 SUMMARY_INPROGRESS is not locked when checking its size in SummaryDirector::canRunSummarizationJob
2016-08-10 SPL-124148, SPL-125741, SPL-125743 Captain is delegating Data Model Acceleration search to more than two members concurrently while "acceleration.max_concurrent = 2"
2016-07-21 SPL-124301, SPL-124771, SPL-124770 Data Model Acceleration stops running for certain Data Model after success=0 multiple times

Data model and pivot issues

Date resolved Issue number Description
2016-08-17 SPL-126266, SPL-126220 SUMMARY_INPROGRESS is not locked when checking its size in SummaryDirector::canRunSummarizationJob
2016-08-10 SPL-124148, SPL-125741, SPL-125743 Captain is delegating Data Model Acceleration search to more than two members concurrently while "acceleration.max_concurrent = 2"
2016-07-21 SPL-124301, SPL-124771, SPL-124770 Data Model Acceleration stops running for certain Data Model after success=0 multiple times

Distributed search and search head clustering issues

Date resolved Issue number Description
2016-09-06 SPL-115008 Distributed searches with multivalue fields might hang while retrieving results from peers.
2016-08-31 SPL-126603, SPL-125138 The description of shc_local_quota_check in limits.conf.spec is inaccurate
2016-08-18 SPL-121163, SPL-108140 "splunk show shcluster-status" incorrectly mentions "search head pool" instead of "search head cluster"
2016-08-17 SPL-119113, SPL-116466 Uneven scheduled search delegation between SHC members
2016-08-16 SPL-125817, SPL-126217, SPL-126218 Splunk incorrectly reports that historical concurrent system-wide searches had been reached
2016-08-16 SPL-117774, SPL-126712, SPL-126713, SPL-126714, SPL-126715 Document cumulativeRTSrchJobsQuota and cumulativeSrchJobsQuota are not supported with SHC in authorize.conf.spec
2016-08-12 SPL-116028, SPL-126451, SPL-126452, SPL-126453, SPL-126454 ERROR SearchResultParserExecutor - Encountered an error deserializing SearchResultsInfo from ResultsStream header.
2016-08-10 SPL-124148, SPL-125741, SPL-125743 Captain is delegating Data Model Acceleration search to more than two members concurrently while "acceleration.max_concurrent = 2"
2016-08-01 SPL-122601, SPL-125456, SPL-125457 Scheduled searches periodically skipped in search-head cluster allegedly due to user-scoped search quota exceeded for "system" user
2016-07-28 SPL-112018, SPL-123777, SPL-123770, SPL-123771 Lookup Tables With Zero Bytes Are Not Replicated in Search Head Clustering
2016-07-21 SPL-124301, SPL-124771, SPL-124770 Data Model Acceleration stops running for certain Data Model after success=0 multiple times

Universal forwarder issues

Date resolved Issue number Description
2016-07-14 SPL-123796, SPL-123744 etc/auth/splunkweb directory shouldn't exist on the UF

Monitoring Console/DMC issues

Date resolved Issue number Description
2016-08-04 SPL-119348, SPL-121814, SPL-121812, SPL-121813 DMC doesn't support Cluster Label with a space in it

Windows-specific issues

Date resolved Issue number Description
2016-08-16 SPL-120078, SPL-126605, SPL-126606, SPL-126607, SPL-126608 splunk-admon.exe fails to update internal 'admon://NearestDC' configuration when Domain Controller is changed.
2016-07-28 SPL-124913, SPL-114570 Large delays in Windows Security Event Logs

Authentication and Authorization issues

For a list of security issues, please see the Security Advisory. A list of all recent advisories can be found in the Security Portal.

Date resolved Issue number Description
2016-08-19 SPL-121846, SPL-126843, SPL-126842, SPL-126845 roleMap_SAML stanza configuration is inconsistent

Admin and CLI issues

Date resolved Issue number Description
2016-08-05 SPL-123834, SPL-125240 CLI commands such as "show cluster-status" results in core dump
2016-07-21 SPL-121746, SPL-121990, SPL-124762 Increase default value for max_chunk_queue_size from 1MB to 10MB

Unsorted issues

Date resolved Issue number Description
2016-08-26 SPL-127079, SPL-127095 Duplicate events with indexerDiscovery following outages on indexer cluster.
2016-08-03 SPL-108622, SPL-122893, SPL-125721 Licenser skipping RolloverSummary event some days with Splunk running continuously, only fixed by restart
2016-07-25 SPL-123987, SPL-123622 Clustered indexers frequently crashing in TimeoutHeap::checkClockSkew

Uncategorized issues

Date resolved Issue number Description
2016-08-22 SPL-125716, SPL-125701 Files that have already been indexed and rolled gets re-indexed
2016-08-15 SPL-122351, SPL-126670, SPL-126671 Single line events are indexed as multi-line ones with timestamp around midnight
2016-08-09 SPL-121463, SPL-126158 HTTP Event collector -> Global settings -> Footer div covers the index dropdown and does not allow scrolling
2016-08-08 SPL-125545, SPL-124791 _si field isn't returned as part of search results in case of "All Time(Real Time)"
PREVIOUS
Transparent huge memory pages and Splunk performance
  NEXT
6.3.6

This documentation applies to the following versions of Splunk® Enterprise: 6.3.7, 6.3.8, 6.3.9, 6.3.10, 6.3.11, 6.3.12, 6.3.13, 6.3.14


Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters